ChatBy.Link Privacy Policy
DIGIORUM INC. operates ChatBy.Link ("ChatBy.Link", "we", "us", or "our").
This Privacy Policy explains how ChatBy.Link collects, uses, discloses, retains, and protects personal information in connection with the Service.
This Privacy Policy is intended for the United States market.
1. Scope
This Privacy Policy applies to:
- Platform Users who create accounts and use Portal;
- End Customers who open or complete public chat links;
- people who receive email or SMS messages sent through the Service;
- people whose information is included in transcripts, attachments, collected data, exports, notifications, webhooks, support messages, or billing and usage records;
- visitors who interact with ChatBy.Link websites or support channels.
End Customers do not need Portal accounts, but the public chat experience can collect personal information, chat transcripts, attachments, device information, and any information entered during the chat.
2. Our Role and Platform User Responsibility
For account registration, billing, support, security, analytics, product administration, and our own business operations, ChatBy.Link determines why and how certain personal information is processed.
For chat transcripts, collected business data, attachments, recipients, webhook payloads, and information requested through a Platform User's chat template, the Platform User usually controls the purpose of collection and use. In those cases, ChatBy.Link processes the information to provide the Service and is intended to act as a service provider or processor where U.S. state privacy laws use those concepts.
Platform Users are responsible for giving End Customers appropriate notices, obtaining required consents, limiting collection to lawful purposes, and complying with laws that apply to their use case.
3. Notice at Collection
We may collect the categories of personal information below.
| Category | Examples | Main purposes |
|---|---|---|
| Identifiers | name, email, phone number, account ID, OAuth ID, recipient contact details, session IDs | account access, delivery, support, security, session management |
| Account and profile data | business name, mailing address, billing address, plan, preferences | account setup, profile, billing support, service operation |
| Authentication data | password hashes, confirmation status, OAuth linkage, sign-in metadata | account access, security, fraud prevention |
| Chat content | messages, transcripts, prompts, extraction rules, completion messages, operator messages | provide AI-assisted chat, produce collected data, show sessions, exports, notifications |
| Collected business data | structured JSON extracted from a chat, summaries, appointment details | provide Portal session review, export, notification, webhook, scheduling features |
| Attachments | file name, content type, size, upload time, stored file content | provide attachment upload, review, download, security, support |
| Communications data | email/SMS templates, recipients, confirmation codes, delivery status, support messages | send links, send notifications, support, troubleshooting |
| Billing data | Stripe customer IDs, checkout status, subscription state, plan assignments, billing events | paid checkout, subscription management, fraud prevention, accounting |
| Usage and analytics data | usage counts, plan limit counters, feature activity, session status, completion timing, logs | quotas, diagnostics, product analytics, security, reliability |
| Device and technical data | IP address, browser, device information, timestamps, request metadata, errors | security, debugging, abuse prevention, performance |
| Integration data | webhook URLs, headers, HMAC settings, delivery attempts, response status | provide webhook delivery and diagnostics |
| Support context | support-chat text, visible page context summaries, safe diagnostic metadata | answer support questions, troubleshoot, improve support |
We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
4. Sources of Personal Information
We collect personal information from:
- Platform Users;
- End Customers;
- message recipients;
- public chat sessions;
- files uploaded through chats;
- configured integrations and webhook receivers;
- payment processor confirmations;
- OAuth providers;
- SMS and email providers;
- logs, devices, browsers, and service telemetry;
- support interactions.
5. How We Use Personal Information
We use personal information to:
- create, authenticate, and secure accounts;
- provide Portal and public chat links;
- run AI-assisted chat and structured data extraction;
- store transcripts, collected data, attachments, and session metadata;
- show dashboards, analytics, usage, billing, and session history;
- send chat links, event notifications, confirmation codes, and service messages;
- process subscriptions through Stripe-hosted billing flows;
- deliver webhooks and troubleshoot delivery;
- provide support and support chat;
- enforce plan limits, quotas, and capabilities;
- detect abuse, protect accounts, prevent fraud, and maintain security;
- debug errors, monitor reliability, and improve the Service;
- comply with legal obligations, enforce terms, and protect rights.
6. AI Processing
The Service uses third-party AI providers and AI-related infrastructure to generate chat responses, extract structured data, summarize, troubleshoot, or support other Service features.
Chat prompts, chat messages, transcripts, extracted data, support messages, and related context may be sent to AI providers as needed to provide the Service.
ChatBy.Link does not guarantee that third-party AI providers will not use submitted data for training, model improvement, abuse monitoring, or other provider purposes unless a separate signed agreement or provider-specific terms expressly says so.
We recommend that Platform Users avoid collecting secrets, payment card data, government identifiers, medical data, children's data, and other sensitive information through AI-assisted chats unless a separate written agreement and legal review covers that use.
7. How We Disclose Personal Information
We may disclose personal information to:
- Platform Users, for sessions, transcripts, collected data, attachments, exports, dashboards, notifications, and webhooks they own or configure;
- End Customers, when chat messages, confirmations, or completion messages are shown in the chat experience;
- AI providers, for AI-assisted responses, extraction, support, or related functionality;
- hosting, database, storage, security, logging, monitoring, analytics, and infrastructure providers;
- Stripe or other payment processors for checkout, subscription, billing, fraud prevention, and payment support;
- Google or other OAuth providers for sign-in;
- SMS providers for text message delivery;
- email providers for transactional, notification, support, or link-send email delivery;
- webhook endpoints configured by Platform Users;
- professional advisors, insurers, auditors, and legal service providers;
- government authorities, regulators, courts, or law enforcement where required by law or necessary to protect rights, safety, and security;
- business transaction parties in connection with a merger, acquisition, financing, reorganization, asset sale, or similar transaction.
Platform Users are responsible for their own disclosure of exported data, webhook payloads, downloaded attachments, and information they collect or copy from the Service.
We do not currently publish a separate subprocessor list. The categories above describe the types of service providers and third-party recipients involved in providing the Service. We may update this Privacy Policy or provide additional notices if our provider categories materially change.
8. No Sale of Personal Information
We do not sell personal information.
We do not use or disclose personal information for cross-context behavioral advertising.
9. Sensitive Information and Regulated Uses
Chat messages, collected data, and attachments may contain sensitive personal information if a Platform User asks for it or an End Customer provides it.
The Service is not currently intended for regulated health intake, HIPAA-covered workflows, medical records, consumer reports, background checks, tenant screening reports, employment screening reports, credit decisions, insurance decisions, or AI-only significant decisions under the standard Terms.
HIPAA-covered workflows may be considered for a future product release. Before you submit protected health information ("PHI"), ChatBy.Link must sign a separate HIPAA Business Associate Agreement ("BAA") with the covered entity or business associate responsible for the PHI and must enable the applicable HIPAA-covered workflow in writing. Standard Terms and this Privacy Policy alone do not authorize PHI processing.
Do not submit children's data, health data, biometric data, genetic data, Social Security numbers, government identifiers, payment card data, protected-class data, or other sensitive information unless you have confirmed that the use is lawful and covered by an appropriate written agreement with us.
10. Email and SMS
The Service may send chat links, notifications, confirmation codes, support messages, or billing-related messages by email or SMS.
Platform Users are responsible for ensuring that they have permission to contact recipients through the selected channel and for honoring any opt-out, unsubscribe, "STOP", or consent requirement that applies to their messages.
We may keep delivery metadata, masked recipient information, provider status, timestamps, failure codes, and related logs for security, troubleshooting, compliance, and quota purposes.
11. Webhooks and Exports
When a Platform User configures webhooks, the Service may send personal information to the configured endpoint. Webhook payloads may include session metadata, collected data, transcript-derived data, attachment metadata, or other fields selected by the Platform User.
When a Platform User exports data, the exported file may include personal information. The Platform User is responsible for securing and controlling exported data after download.
12. Attachments
End Customers may upload attachments where the Platform User's plan and configuration allow it. Attachments are linked to the session and may be visible to the Platform User who owns the session.
The current supported attachment extensions are .pdf, .jpg, .jpeg, .png, .doc, .docx, and .heic. The current baseline maximum attachment size is 10 MB, but the active limit is controlled by Service configuration and may change.
Attachment metadata may appear in Portal and exports. Raw attachment file content is not included in dialog export.
13. Support Chat
Portal may include a support chat for Platform Users. Support chat may process user-entered support messages and a limited, sanitized summary of the current Portal page so the support assistant can answer page-specific questions.
Support chat history is not provided as persistent account history. It may be scoped to the current page session and may disappear after reload, navigation, device change, or session end.
Do not send secrets, card data, full transcripts, raw collected data, or attachment contents through support chat.
14. Cookies and Similar Technologies
We may use cookies, session storage, local storage, logs, and similar technologies to:
- keep Platform Users signed in;
- protect sessions and prevent fraud;
- remember preferences;
- operate public chat links;
- measure usage and reliability;
- debug errors and improve the Service.
We do not currently use marketing cookies, retargeting pixels, analytics pixels, heatmaps, or advertising networks.
15. Data Retention
We retain personal information for as long as needed to provide the Service, maintain accounts, preserve chat history, operate billing and usage records, comply with law, resolve disputes, enforce agreements, prevent abuse, and maintain security.
Data associated with an inactive account may be deleted at our discretion after 6 months of account inactivity. Inactivity means no Portal logins and no active chats or meaningful chat activity during that period. Paid accounts are excluded from inactivity deletion while payment is current.
We will attempt to provide advance notice by email before inactivity deletion. You are responsible for keeping your account email current.
Backups may be retained for up to 1 year. Logs may be retained for up to 2 years. Billing, tax, fraud, chargeback, and dispute records may be retained for up to 7 years or longer if required by law.
Some information may be retained longer where necessary for billing, tax, accounting, security, legal compliance, fraud prevention, dispute resolution, backup, audit, or legitimate business purposes.
16. Security
We use technical, administrative, and organizational measures designed to protect personal information. These may include TLS in transit, password hashing, owner-scoped access controls, restricted access, provider secrets kept out of source code, safe logging practices, webhook signature support, and monitoring.
No system is perfectly secure. You are responsible for using strong credentials, protecting account access, limiting link password distribution, securing exported files, and protecting systems that receive webhooks.
17. Your Privacy Choices and Rights
Depending on where you live, you may have rights to request access, deletion, correction, portability, information about disclosures, limitation of sensitive personal information, opt-out of sale or sharing, and non-discrimination for exercising privacy rights.
California residents may have rights under the California Consumer Privacy Act, including the right to know, delete, correct, opt out of sale or sharing, limit certain uses of sensitive personal information, and not be discriminated against for exercising privacy rights.
Because many End Customer records are collected at the direction of a Platform User, we may need to refer certain requests to the Platform User or verify the request with that Platform User.
To submit a privacy request:
- Email: info@digiorum.com
- Web form: Not currently available
- Postal address: 5716 Corsa Ave, Suite 110, Westlake Village, CA 91362
We may need to verify your identity before responding. We will respond as required by applicable law.
18. Children
The Service is not intended for children under 13, and Platform Users must not use the Service to collect information from children under 13.
If you believe a child under 13 provided personal information through the Service, contact us at info@digiorum.com so we can review and take appropriate action.
19. International Data Transfers
The Service is intended for the United States market. Personal information may be processed in the United States and other locations where we or our service providers operate.
We do not intentionally target users outside the United States.
20. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If changes are material, we will provide notice as required by law or as reasonably appropriate for the change.
The "Last updated" date shows when this Privacy Policy was last revised.
21. Contact
Questions about this Privacy Policy or privacy requests:
- Email: info@digiorum.com
- Postal address: 5716 Corsa Ave, Suite 110, Westlake Village, CA 91362